Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Adobe acknowledges critical remote vulnerability in Flash, exploits already in the wild
AppleInsider ^ | Sunday, January 25, 2015 | By AppleInsider Staff

Posted on 01/25/2015 9:08:43 PM PST by Swordmaker

Adobe on Saturday released an updated version of its Flash player software that patches an undisclosed vulnerability which could allow remote attackers to take control of Macs or PCs, urging users to update as the problem is being actively exploited by malicious actors.

Flash versions up to and including 16.0.0.287 on OS X and Windows and 11.2.202.438 on Linux are susceptible to the attack, the cause of which has yet to be detailed. Mac users with Adobe's automatic update feature enabled should begin receiving updates to version 16.0.0.296 immediately, and the company is preparing a standalone patch for manual installation to be released this week. Adobe is also working with Google to update the embedded version of Flash included in the Chrome browser.

The vulnerability — which has been assigned CVE number 2015-0311 — is "being actively exploited in the wild via drive-by-download attacks against systems running Internet Explorer and Firefox on Windows 8.1 and below," Adobe said in a security advisory. A "drive-by-download" attack is one in which software is downloaded to a user's computer without their knowledge or explicit consent.

Adobe defines CVE-2015-0311 as "critical," meaning a "vulnerability, which, if exploited would allow malicious native-code to execute, potentially without a user being aware."

Users can check the version of Flash installed on their system by visiting Adobe's About Flash Player page or right-clicking on Flash content in their browser and choosing "About Adobe (or Macromedia) Flash Player" from the contextual menu. Instructions for enabling automatic updates or manually updating Flash can be found here.


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: adobe; adobeflash; adobeflashplayer; computers; computing; flash
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-68 next last
To: moose07

Thanks for the ping!


41 posted on 01/26/2015 8:04:07 AM PST by Alamo-Girl
[ Post Reply | Private Reply | To 20 | View Replies]

To: ken in texas; jonatron; deoetdoctrinae; Swordmaker
Anyone who wants to find out what version of Adobe is on the computer they are using can go here:
http://helpx.adobe.com/flash-player/kb/installation-problems-flash-player-windows.html -
jonatron
re: Checked just now, and I have version 16.0.0.296, which I assume patched the vulnerability. - deoetdoctrinae
Interesting. I just checked Adobe's site and it still lists 16.0.0.287 as the current version. A scan with Secunia PSI shows the latest version to be 16.0.0.296 but Adobe doesn't seem to have it.
I used jonatron’s link, now a day later, and it seems that Adobe has pushed out a beta:
Congratulations, your computer has the latest Flash Player beta version installed. (Your version 16.0.0.296 Latest version 16.0.0.287 )
Thanks, Adobe - I guess . . .
Be not the first by whom the new are tried,
Nor yet the last to lay the old aside.

Alexander Pope, An Essay on Criticism, 1711
http://www.quotationspage.com/quote/2031.html

I guess I’m the guinnie (sp) pig.

42 posted on 01/26/2015 8:14:38 AM PST by conservatism_IS_compassion ('Liberalism'; is a conspiracy against the public by wire-service journalism.)
[ Post Reply | Private Reply | To 33 | View Replies]

To: moose07

Yeah, I forwarded this to my help desk kids. I’ve been letting them handle pushing out the updates.

Much fun that this happens in the middle of testing for the students. Last week, it was Java that triggered a Chrome update as well...


43 posted on 01/26/2015 8:32:44 AM PST by Dead Corpse (A Psalm in napalm...)
[ Post Reply | Private Reply | To 34 | View Replies]

To: conservatism_IS_compassion

Thanks for the info. Maybe Adobe will get this straightened our before the next big issue pops up. ;-)


44 posted on 01/26/2015 8:36:20 AM PST by ken in texas
[ Post Reply | Private Reply | To 42 | View Replies]

To: moose07

Wonder how they patch vulnerabilities without closing the bought and paid for backdoors the government asked for?


45 posted on 01/26/2015 9:36:26 AM PST by Darksheare (Those who support liberal "Republicans" summarily support every action by same.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Darksheare

Very badly ....I mean carefully. :)


46 posted on 01/26/2015 9:45:47 AM PST by moose07 (The Camels have reached the parking lot. Shields up!)
[ Post Reply | Private Reply | To 45 | View Replies]

To: conservatism_IS_compassion

Guinea pig....squeak ,squeak. :)


47 posted on 01/26/2015 9:49:06 AM PST by moose07 (The Camels have reached the parking lot. Shields up!)
[ Post Reply | Private Reply | To 42 | View Replies]

To: moose07

Lol, probably so.
I wonder how many patches have been to reopen backdoors they accidentally closed?


48 posted on 01/26/2015 9:49:39 AM PST by Darksheare (Those who support liberal "Republicans" summarily support every action by same.)
[ Post Reply | Private Reply | To 46 | View Replies]

To: Darksheare

It would be logical for them to rewrite the software from end to end, rather than keep playing with it.
It must be a developers nightmare by now.


49 posted on 01/26/2015 9:57:15 AM PST by moose07 (The Camels have reached the parking lot. Shields up!)
[ Post Reply | Private Reply | To 48 | View Replies]

To: Swordmaker
"allow remote attackers to take control of Macs or PCs, urging users to update"

So if ya see your protection pop up to update DON'T!

Like email always click thru your OWN tray icon, not a pop up.

50 posted on 01/26/2015 9:59:49 AM PST by rawcatslyentist (Genesis 1:29 And God said, Behold, I have given you every herb bearing seed,)
[ Post Reply | Private Reply | To 1 | View Replies]

To: moose07

Not to mention junk left over from earlier builds.


51 posted on 01/26/2015 10:06:05 AM PST by Darksheare (Those who support liberal "Republicans" summarily support every action by same.)
[ Post Reply | Private Reply | To 49 | View Replies]

To: Swordmaker

This is the version on Adobe website.

Version 16.0.0.287

Should I install it?


52 posted on 01/26/2015 10:27:08 AM PST by Not gonna take it anymore (If Obama were twice as smart as he is, he would be a wit)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Fresh Wind
Even if you go to the A-dope-y website, by installing the update you always get an extra bonus payload, some sort of useless security scan software from McAfee, and there’s no way I’ve found to opt out of it. I have to delete it every time. Grrr.

I've found that there is a check box somewhere right at the start of their download process to uncheck that eliminates the bloatware on both Windows and Mac installs. . . you have to search their page carefully to find it.

53 posted on 01/26/2015 12:18:18 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 19 | View Replies]

To: Not gonna take it anymore
This is the version on Adobe website.

Version 16.0.0.287

Should I install it?

NO! Look for .296. That's the one that fixes the issue on Windows. Adobe is being its usual cart befor horse's ass self. As I understand it, .296 may be listed as a BETA version.

54 posted on 01/26/2015 12:26:51 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 52 | View Replies]

To: moose07
Well that's CRAP!

Thanks for the ping.

55 posted on 01/26/2015 12:53:12 PM PST by The Cajun (Ted Cruz, Sarah Palin, Mark Levin, Mike Lee, Louie Gohmert....Nuff said.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: Dr. Bogus Pachysandra

Flash Player will typically update automatically, unless you tell it otherwise. My preference is set to notify but not to automatically install.


56 posted on 01/26/2015 1:42:02 PM PST by smokingfrog ( sleep with one eye open (<o> ---)
[ Post Reply | Private Reply | To 39 | View Replies]

To: conservatism_IS_compassion

57 posted on 01/26/2015 2:19:27 PM PST by smokingfrog ( sleep with one eye open (<o> ---)
[ Post Reply | Private Reply | To 42 | View Replies]

To: Swordmaker

This thread is confusing...

So it’s 16.0.0296 that is really the current one that takes care of the fix?

That is what I have.


58 posted on 01/26/2015 3:14:12 PM PST by caww
[ Post Reply | Private Reply | To 54 | View Replies]

To: caww
This thread is confusing...

It is. If you have Flash set up for auto update, then it probably is the most current one for Windows and is the fix. Apparently they still have the old broken one on their manual download website. . . which is über dumb.

59 posted on 01/26/2015 3:58:17 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users contnue...)
[ Post Reply | Private Reply | To 58 | View Replies]

To: Swordmaker

Thank you...then it’s already a done deal...and yes I do automatic updates. But when there’s a question I do check to make certain.


60 posted on 01/26/2015 4:00:31 PM PST by caww
[ Post Reply | Private Reply | To 59 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-68 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson